PatchSiren cyber security CVE debrief
CVE-2026-47130 pdovhomilja CVE debrief
A high-severity vulnerability exists in NextCRM, an open-source customer relationship management software. The issue, identified as CVE-2026-47130, affects versions prior to 0.12.0 and is classified as a Broken Object Level Authorization (BOLA/IDOR) vulnerability. This vulnerability allows any authenticated user, even those with a standard 'member' role, to arbitrarily modify sensitive CRM contacts and targets belonging to other users or organizations, potentially leading to cross-tenant data tampering. Evidence basis is limited to CVE and NVD information.
- Vendor
- pdovhomilja
- Product
- nextcrm-app
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-20
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-07-20
- Advisory updated
- 2026-07-22
Who should care
Organizations using NextCRM versions prior to 0.12.0 should prioritize upgrading to the latest version to mitigate this vulnerability. Additionally, users with access to CRM contacts and targets should be cautious of potential unauthorized modifications. Affected operator, platform, vulnerability-management, and security-team impact should be reviewed.
Technical summary
The vulnerability exists in the CRM contact and target update endpoints of NextCRM. The application fails to verify if the authenticated user has ownership of the specific resource being modified, allowing for arbitrary modifications by any authenticated user. This issue is addressed in version 0.12.0 of NextCRM. Affected product deployments should be reviewed for exposure. The issue allows cross-tenant data tampering, impacting organizations using NextCRM versions prior to 0.12.0. Evidence basis is limited to CVE and NVD information, and defenders should verify affected scope and vendor guidance.
Defensive priority
High
Recommended defensive actions
- Upgrade NextCRM to version 0.12.0 or later
- Review and restrict access to CRM contacts and targets
- Monitor for suspicious activity in CRM systems
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE record was published on 2026-07-20T21:16:47.917Z and was last modified on 2026-07-22T20:50:36.493Z. The NVD entry is currently Deferred. Evidence is limited to CVE and NVD information. Defenders should verify affected scope and vendor guidance.
Official resources
-
CVE-2026-47130 CVE record
CVE.org
-
CVE-2026-47130 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-20T21:16:47.917Z and has not been modified since then. The NVD entry is currently Deferred.